Xacta® IA Manager supports a wide range of governance, risk, and compliance management standards and policies.
Xacta IA Manager includes more than 100 leading regulations and policies for IT risk compliance and management, including:
DOD:
- DIACAP
- DITSCAP to DIACAP transition support
- NSCAP
- Vulnerability Alerts (IAVA, TCNO, others)
Civilian:
- FDCC/SCAP
- FIPS 199
- NIST 800-37 (Guide for Federal IS C&A)
- NIST 800-53/53A (Security Controls for Federal IS)
- NIST 800-60 (Guide for Mapping Information Systems to Security Categories)
- NIACAP
Intelligence Standards:
- CNSS 1253 (Intelligence Community)
- DCID to CNSS transition support
- NISCAP (NSA-specific)
FISMA Reporting:
- Quarterly and Annual Remediation Reports (POA&M)
- OMB C&A Status Quarterly Reporting
- NIST 800-18 (Guide for Developing IT System Security Plans)
- NIST 800-26 (Self Assessment Questionnaire)
|
Industry and International:
- Sarbanes-Oxley
- Common Criteria (selected protection profiles)
- ISO 27002*
- Gramm-Leach-Bliley Act (GLBA)
- NCUA Part 748
- NCUA e-Commerce Guidelines
- Visa Cardholder Information Security Program
- 12 CFR Part 30
- EC-1/EC-2 Checklist
- California SB 1386
- Health Insurance Portability and Accountability Act (HIPAA)
- SANS Top 20 Security Vulnerabilities
- CCE/CPE/CVE/CVSS/OVAL/XCCDF
*Copyrighted material. An additional fee may be required.
Agency Security Requirements:
- Army
- Air Force
- Navy
- DISA (selected STIGs)
- Dept. of Education*
- Dept. of Homeland Security
- Dept. of Justice
- Dept. of State
- Dept. of Transportation (FAA)
- Dept. of Treasury (IRS)
- Dept. of Veterans Affairs
*Agency permission for access required |